Company logo
About usExpertiseOur peopleFrameworksInsightsContactsالعربية
About usAbout usExpertiseExpertiseOur peopleOur peopleFrameworksFrameworksInsightsInsightsContactsContactsالعربيةالعربية
← InsightsArticles

Patient Privacy in Dubai Mainland: Complete Guide

Most patient privacy failures in a Dubai clinic are procurement failures, settled by a hosting or vendor contract long before anyone decides to share a record.

A patient asking for their own file, an insurer asking for the notes behind a claim, and a head office asking to migrate the database are three different questions with three different answers. Works through the federal data protection law, the health-sector limits on where records may be held and sent abroad, and the records conditions the Dubai Health Authority attaches to a facility licence.

By Nour Attorneys / 24 August 2026

A patient asks a Dubai clinic for a copy of their file. An insurer asks the same clinic for the clinical notes behind a claim. A group head office in Europe asks for the whole database to be migrated to a new records system. Three requests, three different answers — and a facility that treats them the same way is going to get one of them wrong.

Patient information in Dubai mainland is governed by more than one set of rules at once: the federal data protection law, health-sector rules on where medical records may be held and when they may leave the country, and the conditions attached to the facility licence by the Dubai Health Authority. This guide sets out what each layer requires, who may lawfully see a patient record, and what to do when something goes wrong.

The Rules That Apply, and to Whom

Processing personal data is governed federally by Federal Decree-Law No. 45 of 2021, the Personal Data Protection Law. Health data is treated as sensitive, which means the grounds for handling it are narrower and the expectations around security are higher than for ordinary business data.

On top of that, health-sector rules restrict where patient data generated in the UAE may be stored and processed, and limit sending it outside the country without the health authority's permission. This is the requirement most often missed, because it is not triggered by a decision to share data — it is triggered by a decision about hosting.

The Dubai Health Authority licenses mainland facilities and professionals and imposes its own medical records conditions through that licence: what a record must contain, how long it must be kept, how it is secured, and how it is handed over if a facility closes or changes hands.

Two jurisdictional points matter. Dubai Healthcare City is a free zone with its own healthcare regulator, so a facility there is not working to the mainland authority's rules. And DIFC and ADGM run their own data protection regimes with their own regulators, so a group with an entity in either centre is complying with more than one standard at the same time.

What Counts as Patient Data

Everything that identifies a patient and everything attached to that identity: the medical record, consultation notes, diagnoses, prescriptions, laboratory and imaging results, insurance and claim files, billing records, genetic and biometric information, and the appointment and messaging logs that sit in the practice management system. Photographs taken for clinical purposes and recordings of teleconsultations are part of the record too, and are frequently left outside the security controls applied to everything else.

The Ground Rules for Handling It

  • Collect for a stated purpose. Record why each category of information is collected, and do not repurpose clinical data for marketing on the basis of the consent given for treatment.
  • Limit access by role. Reception, nursing, clinical, billing and management do not need the same view. Role-based access with individual logins, and an audit log that shows who opened which record, is the control regulators ask about first.
  • Keep records for the period the authority specifies, then dispose of them securely. Indefinite retention "just in case" is its own exposure.
  • Bind your people. Confidentiality obligations belong in employment contracts issued under Federal Decree-Law No. 33 of 2021, which replaced Federal Law No. 8 of 1980, and in a written policy that staff have actually been trained on and signed.
  • Bind your vendors. Records systems, cloud hosts, billing companies, transcription services, marketing agencies and analytics providers all touch patient data. Each needs a written contract covering purpose, security, sub-contracting, location of the data, and what happens to it when the contract ends.

Who May Lawfully See a Record

The patient can. Handle access requests through a documented procedure with identity verification, and do not let the request be answered informally by whoever picked up the phone. Patients also have rights to have inaccurate information corrected, and a clinic needs a way to record a correction without destroying the clinical audit trail.

Clinicians involved in the patient's care can, to the extent needed to provide it. Referral letters and shared-care arrangements should say what is being shared and why.

Insurers and claims administrators receive what is necessary to process the claim, on the basis established when the patient enrolled and consented. Mandatory health insurance means claim data moves routinely between provider, administrator and insurer, and staff should be clear that "routine" is not the same as "unlimited".

Authorities, regulators and courts can compel disclosure. Log what was requested, by whom, under what authority, and what was released — a regulator reviewing a facility later will ask, and so will the patient.

Family members, employers and third parties generally cannot, absent the patient's authority or a specific legal basis. This is where most complaints originate: a well-meant disclosure to a relative or an employer that nobody was authorised to make.

Hosting, Cloud and Cross-Border Transfers

Most privacy problems in healthcare are procurement problems. Before signing for an electronic medical records platform, a teleconsultation tool, a diagnostic AI service or a group-wide reporting system, establish where the data will physically sit, who can access it from outside the UAE, whether any support or backup function is offshore, and what approval a transfer requires. Get that answer in writing from the vendor before the contract is signed, because migrating a live records system later is expensive and disruptive.

Group arrangements deserve the same scrutiny. A head office that wants a consolidated patient database is asking for a cross-border transfer, whatever the internal terminology says.

When Something Goes Wrong

Have a written incident procedure before you need it: who is told inside the facility, who assesses the scope, who notifies the authorities and affected patients, and who preserves the evidence. The first hours of a lost laptop, a compromised account or a misdirected report set the outcome of everything that follows, and improvised handling is what turns an incident into an enforcement action.

A breach in a clinical setting can run down several tracks at once. The health authority can act against the facility licence, and against the professional licence of anyone involved. A complaint about clinical care can be referred to a medical liability committee. And the patient may bring a civil claim. These proceed on different timetables and produce different records, so treat them as one matter with one factual account rather than answering each separately and inconsistently.

Between commercial parties — facility, vendor, insurer, management company — risk can be allocated by contract, and it should sit with whoever is best placed to control it. But liability for gross negligence and wilful misconduct cannot be excluded by agreement, and drafting that tries will not hold. Our work on medical dispute resolution generally starts by mapping the regulatory exposure and the civil exposure together, because the answer given to the regulator becomes evidence in the claim.

A Short Checklist for a Dubai Mainland Facility

Know where your patient records are hosted and who can reach them from abroad. Run role-based access with individual logins and an audit trail. Hold signed data agreements with every vendor that touches the record. Have a written patient access procedure, a retention schedule set to the period the authority requires, and an incident plan with names against each step. Train reception and billing staff, not only clinicians, because most disclosures happen at the front desk.

For advice on patient data handling, vendor and hosting arrangements, or responding to a complaint or regulatory notice, contact the Nour Attorneys team.

Schedule Your Consultation

Disclaimer: The information provided in this article is for general informational purposes only and does not constitute legal advice. Readers should seek professional legal advice tailored to their specific circumstances before making any decisions or taking any action based on the content of this article.

Nour Attorneys Team

Related Resources

Explore more of our insights on related topics:

  • Healthcare Facility Licensing Requirements in the UAE
  • Medical Malpractice Defence Strategies for Dubai Clinics
  • Pharmaceutical Compliance Guidelines for UAE Distributors
  • Patient Privacy Regulations for Multinational Entities
Contact Us

Location

Silver Tower Floor 20, Office 2003 Business Bay Dubai, United Arab Emirates (UAE)
Working hours
Mon–Fri: 9am — 6pm

Navigation

  • About Us
  • Expertise
  • Our People
  • ESG & Sustainability
  • Insights
  • Contacts

Social Media

  • LinkedIn
  • Instagram

Contacts

  • Telephone: +971 58 555 2999
  • WhatsApp: +971 58 555 2999
  • Chatbot
Founding Member - SKP Business Federation
INFO@NOURATTORNEYS.COM
Copyright © 2025 Nour Attorneys. All Rights Reserved
Privacy Policy
Call Us NowChat With Our Team On WhatsApp